iraniangoals.com JavaScript reverse engineering

ID: cia-2010-covert-communication-websites/iraniangoals-com-javascript-reverse-engineering

iraniangoals.com JavaScript reverse engineering by Ciro Santilli 35 Updated +Created
Notably, the password is hardcoded and its hash is stored in the JavaScript itself. The result is then submitted back via a POST request to /cgi-bin/goal.cgi.
TODO: how is the SHA calculated? Appears to be manual.

New to topics? Read the docs here!